[docs] Document Helm values for embedded environment parameters on Kubernetes - #1565
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Frontend HTML artifact readyThe latest frontend build uploaded the This comment updates automatically when a new frontend build artifact is uploaded. |
David Pine (IEvangelist)
left a comment
There was a problem hiding this comment.
🤖 Automated docs-accuracy review — PR #1565
Source of truth: microsoft/aspire@main @ 1cdf7d17248ae78ee018abbc314f772ace5e624d — confirmed to contain the source PR microsoft/aspire#19429 (c596a8e766, milestone 13.6).
⚠️ Branch mismatch (non-blocking). This PR targetsrelease/13.6, which does not exist inmicrosoft/aspire(the newest release branch isrelease/13.5). As in prior hourly runs, I verified againstmain— the only branch that contains the milestone-13.6 source — and flag the mismatch here. It does not affect the verdict.
Phase A — claims: 7 non-narrative claims extracted → 5 verified · 2 contradicted · 0 unverifiable. Both contradictions are in the TypeScript code sample; the C# sample and all prose are correct. See the 2 inline comments.
Phase B — doc-tester: exercised /deployment/kubernetes/clusters/ → HTTP 200, 0 console errors/warnings; the Tabs (C#/TypeScript) + titled-code-figure components the new subsection relies on render correctly in 5 existing instances on the page; the diff adds no new links. One knowledge gap: the locally-running build predates this PR, so the literal new subsection could not be rendered directly.
Verdict: 🔴 REQUEST_CHANGES
The TypeScript example won't compile and won't produce the documented values.yaml (2 contradicted api claims). No Phase B critical issues.
Phase A — Claim verification
The 2 contradicted claims are posted as inline comments on the TypeScript code block. Verified claims are listed below for audit.
✅ 5 verified claims (with evidence, against microsoft/aspire@1cdf7d17)
| # | Type | Claim | Verdict & evidence |
|---|---|---|---|
| C1 | api-behavior | An embedded parameter is declared as its own values.yaml entry "instead of generating a synthetic environment variable for it." |
verified — KubernetesResource.cs:704-719 AllocateAdditionalParameter: "Allocates an embedded parameter without adding a synthetic environment variable." Snapshot #00 shows the nested config.myapp.host: "". |
| C2 | api-shape (C#) | AddParameter("host","localhost") + AddContainer("myapp","nginx").WithEnvironment("SOME_URL", $"http://{host}/test") |
verified — byte-for-byte identical to the product regression test KubernetesPublisherTests.cs:915-919; compiles and produces snapshots #00/#01. |
| C3 | config-key | Generated values.yaml = config.myapp.SOME_URL: "" and host: "" |
verified — matches …EmbeddedParametersInEnvironmentExpressionsPopulateValues#00.verified.yaml. |
| C4 | api-behavior | At deploy time SOME_URL resolves to http://localhost/test via the host override |
verified — ConfigMap snapshot #01: SOME_URL: "http://{{ .Values.config.myapp.host }}/test"; default host: localhost → http://localhost/test. |
| C5 | api-behavior | A conflicting values path "either exactly or after normalization" is rejected rather than silently overwritten | verified — exact-name distinct source throws at KubernetesResource.cs:741-744; normalization collision throws at KubernetesPublishingContext.cs:245-248 (MergeHelmValueMappings, normalized key at L224). |
Phase B — doc-tester report
Focus: new "Environment-specific configuration" subsection · Route: http://localhost:51482/deployment/kubernetes/clusters/#environment-specific-configuration · Tester: doc-tester skill (blind-user; no source reading).
| Category | Passed | Failed | Warnings |
|---|---|---|---|
| Content accuracy (rendered) | n/a | 0 | 0 |
| Components / rendering | 4 | 0 | 0 |
| Links | 1 | 0 | 0 |
Critical issues: none.
Warnings: none.
Passed checks
- Page health:
GET /deployment/kubernetes/clusters/→ 200, title "Deploy to Kubernetes clusters | Aspire". 0 console errors, 0 warnings (8 info messages). - Tabs component (C# / TypeScript,
syncKey='aspire-lang'): renders correctly in 5 existing instances on this page ("Configure your AppHost", "Configure a container registry", "Helm settings", "Node pools", "Per-resource customization") — each atablistwithtab "C#" [selected]+tab "TypeScript"and a populatedtabpanel. High confidence the new subsection's tabs render. - Titled code figures render for existing blocks; the new subsection reuses the same
title=mechanism forAppHost.cs,apphost.mts, andvalues.yaml. - Insertion region intact: "Environment-specific configuration" H2 → "Use external parameters…" (
/fundamentals/external-parameters/, site-relative + trailing slash) → "Service discovery" H3; both anchors resolve. - No new links introduced by the diff (prose + C#/TS code + YAML only), so no link-validation risk is added.
Knowledge gap — running build predates PR #1565
- The locally-running frontend does not contain this change (page source lacks "synthetic environment variable" and
refExpr); it's served from a sibling worktree that predates the PR. - I therefore could not render the literal new subsection. Instead I validated page health, confirmed every component the subsection depends on already renders on the same page, and confirmed the insertion anchors + no-new-links.
- Recommendation: reasonable to accept — component reuse + clean page health make a render failure very unlikely; a follow-up render on a build that includes the PR would fully close the gap. (Code-sample correctness is separately covered by Phase A, which found the TypeScript-tab API defects flagged inline.)
Automated review · Phase A read microsoft/aspire@main 1cdf7d17 · Phase B via doc-tester (blind-user, Playwright). Branch-mismatch caveat applies as noted.
Adam Ratzman (adamint)
left a comment
There was a problem hiding this comment.
No additional issues beyond the existing review threads.
…ps (#1780) ## Summary <!-- Describe what this pull request changes and why. --> Reconcile the 13.6 wiki audit and **all 25 open `docs-from-code` proposals targeting `release/13.6`** against the actual release source. Add missing canonical guidance rather than putting all coverage in What's new. This is a new, isolated feature PR into `release/13.6`; it does not update the release rollup #1599, merge or close another proposal, or push directly to a release branch. **Draft with explicit remaining packaging/validation gates:** the six REPL walkthroughs are source-verified, but current publicly available 13.6 packages do not contain the late `WithRepl` exports. Generated API catalogs have deliberately not been fabricated or refreshed from 14.x. See the open checklist below. ### Evidence baseline - Documentation base: `717442f6666948bcf77f3d704dc2dadf7c080ec2`. - Product source of truth: [`microsoft/aspire@e8fd6fbb954f50ccd2e66479538392f65e13e71d`](https://github.com/microsoft/aspire/tree/e8fd6fbb954f50ccd2e66479538392f65e13e71d), current `release/13.6` at audit time. Source was read from that Git object, not the stale source working directory. - [13.6 wiki](https://github.com/microsoft/aspire/wiki/13.6-Change-log) snapshot `8e01a371d4f16a1306e48174d4cf1fdeca714348`, whose cutoff is product PR 20511. Later backports 20541/20546/20548 are included here. - Proposal base branches alone were **not** used as proof of release membership. Direct ancestry and known release backports were checked. Four fallback-targeted proposals are excluded below. - Wiki link corrections: its REPL link #1752 actually covers Sandboxes; the REPL proposal is #1740. Its AOT link #1714 covers PFX certificates, not AOT. ### Complete audit-gap checklist Checked items mean documentation coverage is implemented, not that cloud deployment or every product runtime scenario was executed. - [x] **1. Dotnet API graduation:** correct removal to **13.6**, not 14.0, in What's new, both Dotnet guides, and the diagnostic page; preserve the prerelease package caveat. This applies to core `AddDotnetProject`, `DotnetProjectResource`, and related `WithBuildEnvironment` overloads, not all uses of the diagnostic. Source: microsoft/aspire#20496. - [x] **2. Sandboxes:** remove obsolete API suppressions in the article and deployment guide while preserving Azure service preview/access and prerelease package limitations. Source: microsoft/aspire#20483. - [x] **3. Docked REPL documentation:** all six PostgreSQL/MySQL/MongoDB/SQL Server/Redis/Valkey guides plus the article now cover opt-in `WithRepl`/`withRepl`, run-only availability, actual client privileges, credential handling, and explicit exit versus closing a viewer. Source: microsoft/aspire#20419, backport of microsoft/aspire#20231. Package-backed checks remain open below. - [x] **4. Terminal CLI flag:** update current 13.6 article, `with-terminal`, and all three terminal command references. Preserve `terminals.v1` and experimental hosting API distinctions. Current configuration/schema data had no flag entry to remove; historical 13.5 notes remain historical. Source: microsoft/aspire#20548. - [x] **5. First-party Rust:** rewrite both canonical Rust guides around `Aspire.Hosting.Rust`; document Cargo versus application arguments, typed targets, debugging, generated Dockerfiles, workspace context, ABI constraints, and Toolkit migration. Bacon remains explicitly Toolkit-only. Add exact first-party package mapping. Source: microsoft/aspire#18906 and current Rust README. - [x] **6. Agent setup:** align command reference, skills guide, AI-agent guide, and article on MCP opt-in, `--mcp`, chained/non-interactive behavior, seven-skill catalog, Project v2 migration, and Copilot app detection. Also fix stale default-selection text: all applicable bundle skills are preselected; companion tools remain opt-in. Sources: microsoft/aspire#19893, microsoft/aspire#20405, microsoft/aspire#19820. - [x] **7. Deno AppHost runtime:** document Deno 2+ detection, commands, permissions, native watch/type checking, doctor, and `DENO_CERT`, separately from Deno guest hosting. Source: microsoft/aspire#18627, distinct from microsoft/aspire#18628. - [x] **8. Native AOT / Fluent UI v5:** concise article, dashboard exploration, and standalone guidance; automatic packaged-dashboard selection, no invented performance figures. Source: microsoft/aspire#19565 and release packaging sources. - [x] **9. NuGet:** document bundled in-process operations, credential providers, non-interactive authentication, and realistic troubleshooting. Correct the proposal's `dotnet nuget locals` authentication advice: cache commands do not authenticate a feed. Source: microsoft/aspire#20391. - [x] **10. Multithreaded builds:** article and coordinated-build guide explain `-mt`, SDK detection, distinct project/file-based SDK floors, and fallback. Source: microsoft/aspire#20441. - [x] **11. Radius:** add a real deployment guide with C#/TypeScript setup, recipe-backed connections versus local endpoints, per-resource credential behavior, unauthenticated Redis limitation, secret exposure boundaries, and actionable runtime diagnostics 070–091. Wire navigation and exact package mapping. Source: microsoft/aspire#19555 and release README. - [x] **12. Connection aliases:** replace contradictory no-encoding guidance, retain composed logical-key-first lookup and portable-target behavior, explain collision detection and custom-publisher metadata. Source: microsoft/aspire#19729. - [x] **13. Connector Namespace / Toolbox / provisioning:** add Connector Namespace walkthrough, security/consent/revocation limits and mapping/sidebar; add Foundry Toolbox walkthrough, connection properties, roles, index prerequisites, approval enforcement boundaries, immutable versions, and existing-resource behavior. Extend existing Azure provisioning guide without a duplicate page. Sources: microsoft/aspire#19024, microsoft/aspire#17742, microsoft/aspire#20131. - [x] **14. Remaining high-impact items:** article covers opt-in manifest-aware DNX and new-template CLI bundling (existing SDK guides retained), migration skill and Copilot app detection; canonical inline `CsiVolumeSourceV1`/`VolumeV1.Csi` example, management links, Cosmos vNext telemetry, and AI Inference `GetModelInfoAsync`/`/info` health checks with `DisableHealthChecks`. No Azure OpenAI health-check claim. Sources: microsoft/aspire#19310, microsoft/aspire#19076, microsoft/aspire#19826, microsoft/aspire#20070, microsoft/aspire#15671, microsoft/aspire#15969. - [x] **15. All 25 proposal dispositions:** listed below, including newer dashboard backports and four exclusions. Existing Sandbox inference coverage is retained rather than copied from a stale draft. - [ ] **16. Refresh generated API/catalog/Twoslash data from an official post-backport 13.6 build.** Existing `26473.12`/`a11eca96` data remains untouched. The newest public `dotnet9` feed package checked, `13.6.0-preview.1.26474.10` at `43496a2a306c81c862c947b11b4f4e5494b6fe08`, still has no Redis `WithRepl` in its actual package XML. Do not use 14.x, hand-edit declarations, or attribute source changes to older binaries. - [ ] **Validate the six REPL examples against that actual post-backport SDK and running clients.** Their new TypeScript fences are plain TypeScript, not annotated with unsupported Twoslash data. No existing diagnostics are allowlisted or suppressed; no generated API exports are fabricated. Enable Twoslash when the genuine catalog catches up. ### All 25 open proposal dispositions and provenance Text is selectively adapted from these proposals, not merged wholesale. #1778 and #1748 are authored by @sebastienros; the other proposals are authored by the Aspire repo bot. The table credits the associated product-change authors where supplied by the proposals. Existing PRs remain open and unchanged. | Docs PR | Release source / credited product author | Disposition | | --- | --- | --- | | #1778 | microsoft/aspire#19729 — @sebastienros | **Adopted:** canonical connection-string alias correction, including logical-first resolution and migration. | | #1771 | microsoft/aspire#20481 — @sebastienros | **Excluded:** flat polyglot feature keys are not in the audited release tip; no verified backport. Preserve release key names. | | #1770 | microsoft/aspire#20525 → microsoft/aspire#20548 — @mitchdenny | **Corrected/adopted:** command guides plus the still-current 13.6 article, which the proposal incorrectly treats as historical. | | #1769 | microsoft/aspire#20416 — @JamesNK | **Excluded:** brand hover change has no verified 13.6 membership/backport. | | #1768 | microsoft/aspire#20523 → microsoft/aspire#20546 — @JamesNK | **Adopted:** run pin/unpin preserves selector and current selection. | | #1766 | microsoft/aspire#20537 → microsoft/aspire#20541 — @mitchdenny | **Adopted:** terminal dock empty state. | | #1761 | microsoft/aspire#20490 → microsoft/aspire#20496 — @eerhardt | **Corrected:** graduation is 13.6, package remains prerelease, Blazor-specific exception retained. | | #1760 | microsoft/aspire#20436 — @eerhardt | **Excluded:** CLI net11/tools-any retarget is not in the audited release; no fallback-base inference. | | #1748 | microsoft/aspire#20131 — @sebastienros | **Adopted:** extend existing provisioning guide with service-specific models/lookups and projection limits. | | #1744 | microsoft/aspire#20337 → microsoft/aspire#20441 — @karolz-ms | **Adopted:** precise SDK-conditional multithreaded build coverage. | | #1740 | microsoft/aspire#20231 → microsoft/aspire#20419 — @mitchdenny | **Adapted:** all six guides; TypeScript-first tabs, source-verified lifecycle/security. Actual post-backport SDK/runtime gate is open above. | | #1738 | microsoft/aspire#20158 → microsoft/aspire#20405 — @karolz-ms | **Partly already covered / completed:** existing seven-skill catalog retained; add project migration guidance and correct command catalog/defaults. Do not misclassify the bundled skill as a companion tool. | | #1735 | microsoft/aspire#20334 — @karolz-ms | **Excluded:** enhanced startup errors are not in the audited release; no verified backport. | | #1731 | microsoft/aspire#19847 → microsoft/aspire#20391 — @eerhardt | **Corrected/adopted:** in-process NuGet and real authenticated-restore troubleshooting, not cache-command authentication. | | #1719 | microsoft/aspire#20299 → microsoft/aspire#20407 — @JamesNK | **Corrected/adopted:** cookie naming/scoping; identical names can collide but do not guarantee cross-dashboard cookie decryptability or shared sign-in. | | #1664 | microsoft/aspire#20011 — @maddymontaquila | **Adopted:** concise Azure environment icon release note. | | #1628 | microsoft/aspire#17742 — @davidfowl | **Adapted/expanded:** canonical Toolbox examples, consumer contract, role/index prerequisites, approval/security and concurrency limits. | | #1623 | microsoft/aspire#19810 — @mitchdenny | **Already covered:** current Sandbox guide/article already describe compute inference, explicit selection and external endpoints. Preserve that guidance while removing obsolete suppressions. | | #1620 | microsoft/aspire#19243 — @sebastienros | **Adapted:** AKS credential-before-Helm cleanup and destructive-operation warning; omit misleading ambient-context workaround. | | #1614 | microsoft/aspire#19870 — @sebastienros | **Adopted:** typed callback handle behavior in extension authoring and article. | | #1574 | microsoft/aspire#19430 — @mitchdenny | **Adapted:** canonical hostname inheritance, explicit-host precedence, catch-all default backend. | | #1570 | microsoft/aspire#19590 — @karolz-ms | **Adopted:** Dev Tunnel URL regression troubleshooting. | | #1565 | microsoft/aspire#19429 — @mitchdenny | **Corrected/adopted:** Helm embedded parameters with real `refExpr` and `addParameter(name, { value })`, not stringifying a handle or using an invalid actual-SDK overload. | | #1564 | microsoft/aspire#19026 — @karolz-ms | **Corrected/adopted:** C#/TypeScript Dotnet gateway walkthrough. Retain both experimental diagnostics; remove obsolete run-only restriction after microsoft/aspire#19997 publishing support. Avoid imported ambiguous API reference. | | #1499 | microsoft/aspire#19248 — @IEvangelist | **Adopted:** describe exact secret-value redaction and embedded-secret limit; release article already covered the fix. | ### Important source-verified corrections to proposals / earlier audit assumptions - [`BlazorGatewayExtensions.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Blazor/BlazorGatewayExtensions.cs): `AddDotnetProjectBlazorGateway` and the Dotnet `WithBlazorClientApp` overload still carry `ASPIREDOTNETPROJECT001`; the class carries `ASPIREBLAZOR001`. They share `WithBlazorClientAppCore`/`WithBlazorApp` and the publish-companion path. Thus neither blanket diagnostic retirement nor the proposal's old run-only claim is correct. - [`SkillDefinition.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Agents/SkillDefinition.cs) sets bundled skills' `IsDefault=true`; [`AgentInitCommand.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Commands/AgentInitCommand.cs) selects the applicable catalog defaults for both flows. MCP has its own standalone-only binding. - [`TypeScriptAppHostToolchainResolver.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Projects/TypeScriptAppHostToolchainResolver.cs) is the source for Deno flags and certificate variable; guest Deno hosting is separate. - [`Radius README`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Radius/README.md) supplies the resource-specific credential rules and publish diagnostics, not assumptions about local endpoints. ## Third-party links and affiliations <!-- List third-party links and disclose material affiliations. --> Links point to official Microsoft Learn, VS Code Marketplace debugger extensions, Rust/Cargo/Bacon documentation, Radius documentation, and source repositories. No sponsorship, commercial endorsement, or affiliation claim is introduced. Maintainers should supply any personal affiliation disclosure required by policy; automation has not inferred one. ## Validation <!-- List the checks you ran or explain why validation isn't needed. --> - **97 passing focused unit checks** across API-reference authoring/rendering, Twoslash blocks, file-tree formatting, CLI configuration schema, SEO lengths, and resource catalog. - **82 passing structured-data checks**, including exact integration mapping uniqueness and page resolution. - **11 C# samples compile**, zero warnings/errors, using genuine `13.6.0-preview.1.26473.12` packages. Scope: Rust, Connector Namespace, Radius, Toolbox, inline CSI, Helm, Blazor gateway, and provisioning. `Projects.Api/Worker/Client` use compile-only `IProjectMetadata` stand-ins; no claim of running those apps or provisioning cloud resources. - **10 TypeScript samples pass `tsc`** under `strict`, `NodeNext`, and `ES2022` against three **unmodified actual SDK files**, not just the site's declaration bundle. The fixture uses the exact `e8fd6fbb` release `AtsCapabilityScanner` and genuine `26473.12` TypeSystem/code-generator/integration binaries, whose informational source is `a11eca96`. This is an isolated local generation fixture, **not** a claim that official CLI generation or a new packaged release was tested. An attempted restore with the older handed-off local CLI could not discover an AppHost server; the bounded direct generator fixture was used instead. - The SDK scan is **not globally warning-free**: it reports a Radius `withContainerImage` collision on `CSharpAppResource` and an App Configuration `createRoleAssignment` overload collision. None of the compiled examples calls those colliding methods; the warnings are retained in evidence, not suppressed, and no generated declarations were edited. - Browser: Connector Namespace, Radius, both Rust pages, Foundry hosting, and What's new return **HTTP 200**, correct headings, and no rendered Twoslash errors. New guide/article page-local anchors and the cross-page Blazor anchor resolve. Connector/Radius mobile layouts have no horizontal overflow; Connector language-tab interaction works. Standalone Astro preview emits expected `/api/live` 404s because StaticHost is not running. - `git diff --check` passes. No production `pnpm build`, cloud deployment, REPL runtime session, full product suite, or blanket validation of every pre-existing example was performed. - Generated C#/TypeScript API data, declaration bundles, integration catalogs, image catalogs, and contributor data are unchanged. Only the authored package-to-guide mapping is updated. **Before merging:** complete the two packaging/REPL checkboxes above, inspect CI, and obtain human review. This PR intentionally does not close or merge the source documentation proposals. --------- Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Resolve clusters.mdx conflict by keeping the base branch's "Parameters inside environment expressions" section (refExpr-based TypeScript sample) and folding in the PR's values.yaml example, ordered C# first to match the page. Clarify that embedded parameters don't become extra env vars, show the ConfigMap reference, document the manual Helm override path, and describe secret routing, verified against microsoft/aspire c596a8e766 (#19429) snapshots. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The TypeScript example uses an invalid addParameter call and must pass the default value positionally.
Review effort: Lite
Findings: 1
What changed in this PR
Documents Helm values behavior for embedded environment parameters in Kubernetes deployments.
Changes:
- Adds C# and TypeScript examples.
- Documents generated
values.yaml, secret handling, overrides, and conflict rejection.
| File | Description |
|---|---|
src/frontend/src/content/docs/deployment/kubernetes/clusters.mdx |
Documents embedded parameter handling in generated Helm charts. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| @@ -338,28 +352,30 @@ import { createBuilder, refExpr } from './.aspire/modules/aspire.mjs'; | |||
| const builder = await createBuilder(); | |||
| await builder.addKubernetesEnvironment('k8s'); | |||
| const host = await builder.addParameter('host', { value: 'localhost' }); | |||

Documents changes from microsoft/aspire#19429
@mitchdennyWhy this is needed
The source PR fixes how Aspire generates Helm values for parameters that are embedded inside a larger environment-variable expression (e.g. interpolated into a URL). Previously, Kubernetes publishing could emit incomplete Helm output (e.g.
(redacted) because the embedded parameter was not declared as its own values entry. The fix declares embedded config/secret parameters directly invalues.yaml`, resolves composite/conditional expressions at deploy time, and rejects values-path conflicts instead of silently overwriting them. This is a user-facing behavior change to the generated Helm chart output, so the docs need to describe the new values.yaml shape.What changed
src/frontend/src/content/docs/deployment/kubernetes/clusters.mdx: Added a new subsection under "Environment-specific configuration" that documents how Aspire now declares embedded parameters as their ownvalues.yamlentries (with a C#/TypeScript example matching the source PR's reproduction), shows the generated YAML shape, and notes the values-path conflict rejection behavior.No new pages were created; this is an update to an existing page.